Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Nov 11, 2009 | Updated Sep 15, 2017

Backdoor:WinNT/Festi.A

Detected by Microsoft Defender Antivirus

Aliases: Rootkit-Pakes.Q (AVG) Rootkit.27206 (BitDefender) Backdoor.WinNT.Festi (Ikarus) Rootkit.Win32.Tent.iw (Kaspersky) Rootkit.AWLO (Norman) Hacktool.Rootkit (Symantec) Mal_Neb-2 (Trend Micro) Rootkit.Festi.A (VirusBuster)

Summary

Backdoor:WinNT/Festi.A is a backdoor trojan that allows limited remote access and control. It retrieves instructions and commands from a remote attacker by connecting to a remote website and downloading data. The commands could instruct WinNT/Festi.A to distribute spam.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as Microsoft Security Essentials, or the Microsoft Safety Scanner. For more information about using antivirus software, see http://www.microsoft.com/security/antivirus/av.aspx.
Follow us